PHP New User Creation
$begingroup$
I'm learning more about PHP
, so I've decided to create a simple login/create account system. Entering information for creating a new account sends the data to my localhost machine, using MySQLi
and the web server MySQL
. I'm looking for feedback about security, efficiency, and overall code. I would like to kick old habits to the curb before it's too late. Any and all help is appreciated and considered. Thank you in advance!
create.html
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.html</title>
<script src="script.js"></script>
<link rel="stylesheet" type="text/css" href="style.css">
</head>
<body bgcolor="pink">
<center>
<form action="create.php" method="post">
<label>Username</label>
<input type="text" name="username"><br>
<label>Password</label>
<input type="password" name="password"><br>
<label>Re-enter Password</label>
<input type="password" name="confirm_password"><br>
<button type="submit">Create Account</button>
</form>
</center>
</body>
</html>
create.php
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.php</title>
</head>
<body bgcolor="pink">
<?php
$servername = "localhost";
$username = "XXXXXXXXXX"; // Not shown
$password = "XXXXXXXXXX"; // Not shown
$dbname = "Database";
//Create connection
$mysqli = new mysqli($servername, $username, $password, $dbname);
//Test connection
if ($mysqli->connect_error) {
die("Connection failed: " . $mysqli->connect_error);
}
$new_user_usr = filter_input(INPUT_POST, 'username');
$new_user_pwd = filter_input(INPUT_POST, 'password');
$new_user_pwd_conf = filter_input(INPUT_POST, 'confirm_password');
$sql = "SELECT usr, pwd FROM Users";
$result = $mysqli->query($sql);
if($result->num_rows > 0) {
/* If passwords don't match */
if($new_user_pwd !== $new_user_pwd_conf) {
die("Passwords don't match");
}
/* If password isn't between bounds */
if(strlen($new_user_pwd) <= 7 || strlen($new_user_pwd) >= 13) {
die("Password not long enough! Must be at least 8 characters long, but not greater than 12 characters");
}
/* If username is the same as password*/
if($new_user_usr === $new_user_pwd) {
die("Username cannot equal password!");
}
while($row = $result->fetch_assoc()) {
if($row['usr'] === $new_user_usr) {
die("Username already taken");
}
}
$add = "INSERT INTO Users (usr, pwd) VALUES ('$new_user_usr', '$new_user_pwd')";
echo $mysqli->query($add) ? "user created successfully" : "Error: " . $add . "<br>" . $mysqli->error;
}
?>
</body>
</html>
php html mysqli
$endgroup$
add a comment |
$begingroup$
I'm learning more about PHP
, so I've decided to create a simple login/create account system. Entering information for creating a new account sends the data to my localhost machine, using MySQLi
and the web server MySQL
. I'm looking for feedback about security, efficiency, and overall code. I would like to kick old habits to the curb before it's too late. Any and all help is appreciated and considered. Thank you in advance!
create.html
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.html</title>
<script src="script.js"></script>
<link rel="stylesheet" type="text/css" href="style.css">
</head>
<body bgcolor="pink">
<center>
<form action="create.php" method="post">
<label>Username</label>
<input type="text" name="username"><br>
<label>Password</label>
<input type="password" name="password"><br>
<label>Re-enter Password</label>
<input type="password" name="confirm_password"><br>
<button type="submit">Create Account</button>
</form>
</center>
</body>
</html>
create.php
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.php</title>
</head>
<body bgcolor="pink">
<?php
$servername = "localhost";
$username = "XXXXXXXXXX"; // Not shown
$password = "XXXXXXXXXX"; // Not shown
$dbname = "Database";
//Create connection
$mysqli = new mysqli($servername, $username, $password, $dbname);
//Test connection
if ($mysqli->connect_error) {
die("Connection failed: " . $mysqli->connect_error);
}
$new_user_usr = filter_input(INPUT_POST, 'username');
$new_user_pwd = filter_input(INPUT_POST, 'password');
$new_user_pwd_conf = filter_input(INPUT_POST, 'confirm_password');
$sql = "SELECT usr, pwd FROM Users";
$result = $mysqli->query($sql);
if($result->num_rows > 0) {
/* If passwords don't match */
if($new_user_pwd !== $new_user_pwd_conf) {
die("Passwords don't match");
}
/* If password isn't between bounds */
if(strlen($new_user_pwd) <= 7 || strlen($new_user_pwd) >= 13) {
die("Password not long enough! Must be at least 8 characters long, but not greater than 12 characters");
}
/* If username is the same as password*/
if($new_user_usr === $new_user_pwd) {
die("Username cannot equal password!");
}
while($row = $result->fetch_assoc()) {
if($row['usr'] === $new_user_usr) {
die("Username already taken");
}
}
$add = "INSERT INTO Users (usr, pwd) VALUES ('$new_user_usr', '$new_user_pwd')";
echo $mysqli->query($add) ? "user created successfully" : "Error: " . $add . "<br>" . $mysqli->error;
}
?>
</body>
</html>
php html mysqli
$endgroup$
add a comment |
$begingroup$
I'm learning more about PHP
, so I've decided to create a simple login/create account system. Entering information for creating a new account sends the data to my localhost machine, using MySQLi
and the web server MySQL
. I'm looking for feedback about security, efficiency, and overall code. I would like to kick old habits to the curb before it's too late. Any and all help is appreciated and considered. Thank you in advance!
create.html
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.html</title>
<script src="script.js"></script>
<link rel="stylesheet" type="text/css" href="style.css">
</head>
<body bgcolor="pink">
<center>
<form action="create.php" method="post">
<label>Username</label>
<input type="text" name="username"><br>
<label>Password</label>
<input type="password" name="password"><br>
<label>Re-enter Password</label>
<input type="password" name="confirm_password"><br>
<button type="submit">Create Account</button>
</form>
</center>
</body>
</html>
create.php
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.php</title>
</head>
<body bgcolor="pink">
<?php
$servername = "localhost";
$username = "XXXXXXXXXX"; // Not shown
$password = "XXXXXXXXXX"; // Not shown
$dbname = "Database";
//Create connection
$mysqli = new mysqli($servername, $username, $password, $dbname);
//Test connection
if ($mysqli->connect_error) {
die("Connection failed: " . $mysqli->connect_error);
}
$new_user_usr = filter_input(INPUT_POST, 'username');
$new_user_pwd = filter_input(INPUT_POST, 'password');
$new_user_pwd_conf = filter_input(INPUT_POST, 'confirm_password');
$sql = "SELECT usr, pwd FROM Users";
$result = $mysqli->query($sql);
if($result->num_rows > 0) {
/* If passwords don't match */
if($new_user_pwd !== $new_user_pwd_conf) {
die("Passwords don't match");
}
/* If password isn't between bounds */
if(strlen($new_user_pwd) <= 7 || strlen($new_user_pwd) >= 13) {
die("Password not long enough! Must be at least 8 characters long, but not greater than 12 characters");
}
/* If username is the same as password*/
if($new_user_usr === $new_user_pwd) {
die("Username cannot equal password!");
}
while($row = $result->fetch_assoc()) {
if($row['usr'] === $new_user_usr) {
die("Username already taken");
}
}
$add = "INSERT INTO Users (usr, pwd) VALUES ('$new_user_usr', '$new_user_pwd')";
echo $mysqli->query($add) ? "user created successfully" : "Error: " . $add . "<br>" . $mysqli->error;
}
?>
</body>
</html>
php html mysqli
$endgroup$
I'm learning more about PHP
, so I've decided to create a simple login/create account system. Entering information for creating a new account sends the data to my localhost machine, using MySQLi
and the web server MySQL
. I'm looking for feedback about security, efficiency, and overall code. I would like to kick old habits to the curb before it's too late. Any and all help is appreciated and considered. Thank you in advance!
create.html
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.html</title>
<script src="script.js"></script>
<link rel="stylesheet" type="text/css" href="style.css">
</head>
<body bgcolor="pink">
<center>
<form action="create.php" method="post">
<label>Username</label>
<input type="text" name="username"><br>
<label>Password</label>
<input type="password" name="password"><br>
<label>Re-enter Password</label>
<input type="password" name="confirm_password"><br>
<button type="submit">Create Account</button>
</form>
</center>
</body>
</html>
create.php
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="UTF-8">
<title>create.php</title>
</head>
<body bgcolor="pink">
<?php
$servername = "localhost";
$username = "XXXXXXXXXX"; // Not shown
$password = "XXXXXXXXXX"; // Not shown
$dbname = "Database";
//Create connection
$mysqli = new mysqli($servername, $username, $password, $dbname);
//Test connection
if ($mysqli->connect_error) {
die("Connection failed: " . $mysqli->connect_error);
}
$new_user_usr = filter_input(INPUT_POST, 'username');
$new_user_pwd = filter_input(INPUT_POST, 'password');
$new_user_pwd_conf = filter_input(INPUT_POST, 'confirm_password');
$sql = "SELECT usr, pwd FROM Users";
$result = $mysqli->query($sql);
if($result->num_rows > 0) {
/* If passwords don't match */
if($new_user_pwd !== $new_user_pwd_conf) {
die("Passwords don't match");
}
/* If password isn't between bounds */
if(strlen($new_user_pwd) <= 7 || strlen($new_user_pwd) >= 13) {
die("Password not long enough! Must be at least 8 characters long, but not greater than 12 characters");
}
/* If username is the same as password*/
if($new_user_usr === $new_user_pwd) {
die("Username cannot equal password!");
}
while($row = $result->fetch_assoc()) {
if($row['usr'] === $new_user_usr) {
die("Username already taken");
}
}
$add = "INSERT INTO Users (usr, pwd) VALUES ('$new_user_usr', '$new_user_pwd')";
echo $mysqli->query($add) ? "user created successfully" : "Error: " . $add . "<br>" . $mysqli->error;
}
?>
</body>
</html>
php html mysqli
php html mysqli
asked 2 hours ago
David WhiteDavid White
279413
279413
add a comment |
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function () {
return StackExchange.using("mathjaxEditing", function () {
StackExchange.MarkdownEditor.creationCallbacks.add(function (editor, postfix) {
StackExchange.mathjaxEditing.prepareWmdForMathJax(editor, postfix, [["\$", "\$"]]);
});
});
}, "mathjax-editing");
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "196"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcodereview.stackexchange.com%2fquestions%2f214883%2fphp-new-user-creation%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Code Review Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
Use MathJax to format equations. MathJax reference.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcodereview.stackexchange.com%2fquestions%2f214883%2fphp-new-user-creation%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown